Jump to content

Sophos Phish Training emails being quarantined by Office 365 :(


Recommended Posts

Posted (edited)

Hi,

 

Just looking at the email message ID and added the domain

 

eu-west-1.amazonses.com

 

into the sending domain...

 

As in previous post, put the Sophos domains into the 'Simulation URL' section...

Edited by Koldov
Posted

This seems to have fixed it (for us anyway), I'm not sure if that 'sender' domain ever changes but the last few tests have come through ok.

 

PHISH 6.JPG

 

PHISH 7.JPG

 

I have also removed all the other 'Allowed Domains' set in the other 'Anti-Spam' policy (and the IP addresses in the 'Connection Filter').

Posted
This seems to have fixed it (for us anyway), I'm not sure if that 'sender' domain ever changes but the last few tests have come through ok.

 

[ATTACH=CONFIG]63053[/ATTACH]

 

[ATTACH=CONFIG]63054[/ATTACH]

 

I have also removed all the other 'Allowed Domains' set in the other 'Anti-Spam' policy (and the IP addresses in the 'Connection Filter').

 

Thanks for your PM and help.

 

Seems this also fixed it for us:

 

in the 'Advanced Delivery' settings.

 

Sending Domain

eu-west-1.amazonses.com

 

Sending Domain

staysafe.sophos.com

 

Sending IP

54.240.51.52

 

Sending IP

54.240.51.53

 

Allowed Simulation URL

gmailmsg.com

  • 3 months later...
Posted

Good afternoon guys,

 

This thread has been really interesting - It seems as though every time I've done a phishing test (we do it monthly to random users) it will instantly get quarantined until I botch my way around whitelisting the address.

 

I've now removed all of the whitelisted domains/IPs from the anti spam policies and added the Advanced Delivery settings you've advised (with some of the additional Sophos simulated URLs) but I'm still getting quarantined. Did you end up amending the 'High Confidence Phish' setting?

 

I'm glad Defender is doing it's job, but this is maddening!

Posted (edited)

How come people don’t use Microsoft’s built in Defender attack simulations?

 

Adding the IPS to the Connection filter should override high confidence phishing.

 

You can also use the tenant allow feature to allow a domain for 30 days. You can do this after you report an email is clean in threat explorer.

Edited by free780
Posted

Hi Free,

 

Thanks for the reply. We don't have licences for Defender so can't use Investigations, Explorer, Campaigns, Threat Tracker, etc. We do however have Sophos Phish Threat, and have been using it monthly for a while, but every couple of months Microsoft change something that makes the emails get quarantined (I'm doing a copy of the same campaign I did in September & October, with the same dummy sender address and it's suddenly not working).

 

I have removed all of the whitelisted addresses and IPs (including the connection filter IPs as @Koldov mentioned above) that I had set up previously and have the following in my Advanced Delivery rule, but it is still quarantining my test emails:

Advanced Delivery Rules.png

 

Any help would be greatly appreciated!

 

This situation is particularly annoying as we do the phishing tests to show that IT Support are constantly doing work, which prevents me from doing proper work, but when doing these tests (that should take minutes) I spend ages troubleshooting!

Posted
How come people don’t use Microsoft’s built in Defender attack simulations?

 

Doesn't that only apply to those with the appropriate licenses? I guess not everyone has those...

 

"Attack simulation training in Microsoft Defender for Office 365 Plan 2 or Microsoft 365 E5"

 

https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/attack-simulation-training?view=o365-worldwide

 

We got Sophos Phish bundled in with Sophos AV from LGfL, but unfortunately they have somehow let our licenses for it expire so I haven't sent one in a while (and I've been a little preoccupied with other things), but I don't really remember doing anything other than what was described in this thread (but then again, I don't know whether it still works either).

 

It's been a while and a lot has happened since then, but I seem to remember looking at the quarantined messages, where they came from and what rule in the Exchange admin center was using to block them (if it comes from a different domain or says that 'an admin in your organization has set up a spam rule')...

 

I think that MS are still making changes to the way it deals with spam/phishing so it could be that they have done something that has started blocking them again...

 

Sorry I can't be more help!

Posted

Hi @Koldov,

 

I appreciate the reply.

 

I've now found the culprit after looking into the headers - our email filter (Checkpoint) has been intercepting the messages, but passing them through from their IP where they then got trapped. I've added the Sophos IPs to the Checkpoint exclusion rule and it is now working.

 

Many thanks for the help!

  • 10 months later...
Posted

Was working well last year but my recent simulated attacks are not working because as soon as the email lands it's triggering something with Sophos to make it look like the user is clicking the link in the email.

 

Any ideas what could be causing this?

 

The test user hadn't even logged in to Office 365 and he was "caught"

 

Capture.JPG

Posted
I am guessing the link is unique to identify the user and something is following the link to check it and setting off the unique link. What spam system do you use? Would be funny if it was Sophos triggering itself!
Posted
I am guessing the link is unique to identify the user and something is following the link to check it and setting off the unique link. What spam system do you use? Would be funny if it was Sophos triggering itself!

 

Think we may have narrowed it down to our Barracuda Networks' Email Gateway Defense!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...